Hi, I am new here, but I found and ran Combo Fix on my older desktop Dell (which I would like to have working again).
History: I was running a wireless adapter on the computer and AVG but I lost connection to the internet and AVG is way out of date. I can't get online to update but downloaded Combofix to my jump drive and ran it on the machine. Is it infected with something?
I also saw EACFILT in my network connection and was given a warning that it was not verified...what's that about?
Thanks in advance for ANY help on this computer.
Jen
ComboFix 08-01-18.5 - Jennifer 2008-01-19 13:42:06.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.321 [GMT -5:00]
Running from: C:\Documents and Settings\Jennifer\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2007-12-19 to 2008-01-19 )))))))))))))))))))))))))))))))
.
2008-01-19 13:40 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-02-17 18:00 54,784 ----a-w C:\WINDOWS\Internet Logs\xDB71.tmp
2007-02-17 18:00 2,923,520 ----a-w C:\WINDOWS\Internet Logs\xDB70.tmp
2007-01-29 23:27 32,256 ----a-w C:\WINDOWS\Internet Logs\xDB6F.tmp
2007-01-29 23:27 2,851,328 ----a-w C:\WINDOWS\Internet Logs\xDB6E.tmp
2007-01-20 03:15 20,992 ----a-w C:\WINDOWS\Internet Logs\xDB6D.tmp
2007-01-20 03:14 2,843,648 ----a-w C:\WINDOWS\Internet Logs\xDB6C.tmp
2007-01-08 05:04 2,843,136 ----a-w C:\WINDOWS\Internet Logs\xDB6B.tmp
2007-01-07 13:39 61,952 ----a-w C:\WINDOWS\Internet Logs\xDB6A.tmp
2007-01-07 13:39 2,846,720 ----a-w C:\WINDOWS\Internet Logs\xDB69.tmp
2006-12-31 18:13 2,825,728 ----a-w C:\WINDOWS\Internet Logs\xDB68.tmp
2006-12-31 00:15 90,112 ----a-w C:\WINDOWS\Internet Logs\xDB67.tmp
2006-12-31 00:15 2,841,600 ----a-w C:\WINDOWS\Internet Logs\xDB66.tmp
2006-11-12 13:00 20,480 ----a-w C:\WINDOWS\Internet Logs\xDB65.tmp
2006-11-12 13:00 2,801,152 ----a-w C:\WINDOWS\Internet Logs\xDB64.tmp
2006-11-12 12:53 46,080 ----a-w C:\WINDOWS\Internet Logs\xDB63.tmp
2006-11-12 12:53 2,798,080 ----a-w C:\WINDOWS\Internet Logs\xDB61.tmp
2006-10-10 22:01 2,734,080 ----a-w C:\WINDOWS\Internet Logs\xDB60.tmp
2006-10-10 22:00 22,016 ----a-w C:\WINDOWS\Internet Logs\xDB62.tmp
2006-09-04 11:36 35,840 ----a-w C:\WINDOWS\Internet Logs\xDB5F.tmp
2006-09-04 11:36 2,755,072 ----a-w C:\WINDOWS\Internet Logs\xDB5E.tmp
2006-09-01 01:59 2,769,920 ----a-w C:\WINDOWS\Internet Logs\xDB5C.tmp
2006-08-31 22:44 54,272 ----a-w C:\WINDOWS\Internet Logs\xDB5D.tmp
2006-08-23 23:27 92,160 ----a-w C:\WINDOWS\Internet Logs\xDB5B.tmp
2006-08-23 23:24 2,705,408 ----a-w C:\WINDOWS\Internet Logs\xDB5A.tmp
2006-08-16 23:10 2,690,560 ----a-w C:\WINDOWS\Internet Logs\xDB58.tmp
2006-08-16 23:09 113,664 ----a-w C:\WINDOWS\Internet Logs\xDB59.tmp
2006-08-12 18:12 45,568 ----a-w C:\WINDOWS\Internet Logs\xDB57.tmp
2006-08-12 18:12 2,671,616 ----a-w C:\WINDOWS\Internet Logs\xDB55.tmp
2006-08-11 21:08 2,663,424 ----a-w C:\WINDOWS\Internet Logs\xDB53.tmp
2006-08-11 21:08 15,872 ----a-w C:\WINDOWS\Internet Logs\xDB56.tmp
2006-08-11 20:49 36,352 ----a-w C:\WINDOWS\Internet Logs\xDB54.tmp
2006-08-11 20:37 2,664,448 ----a-w C:\WINDOWS\Internet Logs\xDB52.tmp
2006-08-10 22:24 65,536 ----a-w C:\WINDOWS\Internet Logs\xDB51.tmp
2006-08-10 22:24 2,663,424 ----a-w C:\WINDOWS\Internet Logs\xDB50.tmp
2006-08-08 21:24 472,576 ----a-w C:\WINDOWS\Internet Logs\xDB4F.tmp
2006-08-08 21:21 2,633,216 ----a-w C:\WINDOWS\Internet Logs\xDB4E.tmp
2006-08-04 10:39 2,563,072 ----a-w C:\WINDOWS\Internet Logs\xDB4C.tmp
2006-08-04 10:36 318,976 ----a-w C:\WINDOWS\Internet Logs\xDB4D.tmp
2006-08-04 02:13 2,580,992 ----a-w C:\WINDOWS\Internet Logs\xDB4B.tmp
2006-07-23 10:36 127,488 ----a-w C:\WINDOWS\Internet Logs\xDB4A.tmp
2006-07-23 10:35 2,547,712 ----a-w C:\WINDOWS\Internet Logs\xDB49.tmp
2006-07-20 01:29 344,064 ----a-w C:\WINDOWS\Internet Logs\xDB48.tmp
2006-07-20 01:29 2,534,400 ----a-w C:\WINDOWS\Internet Logs\xDB47.tmp
2006-07-16 20:53 2,522,624 ----a-w C:\WINDOWS\Internet Logs\xDB46.tmp
2006-07-13 01:33 2,474,496 ----a-w C:\WINDOWS\Internet Logs\xDB44.tmp
2006-07-13 01:33 1,439,232 ----a-w C:\WINDOWS\Internet Logs\xDB45.tmp
2006-07-12 01:29 2,471,424 ----a-w C:\WINDOWS\Internet Logs\xDB43.tmp
2006-07-07 20:16 2,653,184 ----a-w C:\WINDOWS\Internet Logs\xDB42.tmp
2006-07-07 20:15 2,454,528 ----a-w C:\WINDOWS\Internet Logs\xDB41.tmp
2006-06-26 01:44 2,637,824 ----a-w C:\WINDOWS\Internet Logs\xDB40.tmp
2006-06-26 01:44 2,437,120 ----a-w C:\WINDOWS\Internet Logs\xDB3F.tmp
2006-06-13 17:43 2,415,104 ----a-w C:\WINDOWS\Internet Logs\xDB3E.tmp
2006-06-09 05:02 693,760 ----a-w C:\WINDOWS\Internet Logs\xDB3D.tmp
2006-06-09 05:02 2,414,592 ----a-w C:\WINDOWS\Internet Logs\xDB3C.tmp
2006-06-08 04:33 2,411,520 ----a-w C:\WINDOWS\Internet Logs\xDB3B.tmp
2006-06-06 18:22 92,672 ----a-w C:\WINDOWS\Internet Logs\xDB3A.tmp
2006-06-06 18:22 2,409,472 ----a-w C:\WINDOWS\Internet Logs\xDB39.tmp
2006-06-06 04:22 366,080 ----a-w C:\WINDOWS\Internet Logs\xDB38.tmp
2006-06-06 04:22 2,409,472 ----a-w C:\WINDOWS\Internet Logs\xDB37.tmp
2006-06-05 04:19 798,720 ----a-w C:\WINDOWS\Internet Logs\xDB36.tmp
2006-06-05 04:19 2,409,472 ----a-w C:\WINDOWS\Internet Logs\xDB35.tmp
2006-06-03 03:43 491,520 ----a-w C:\WINDOWS\Internet Logs\xDB34.tmp
2006-06-03 03:43 2,408,960 ----a-w C:\WINDOWS\Internet Logs\xDB32.tmp
2006-06-02 04:29 2,414,080 ----a-w C:\WINDOWS\Internet Logs\xDB31.tmp
2006-06-01 20:29 2,417,152 ----a-w C:\WINDOWS\Internet Logs\xDB30.tmp
2006-06-01 20:29 1,971,712 ----a-w C:\WINDOWS\Internet Logs\xDB33.tmp
2006-05-29 03:13 2,404,352 ----a-w C:\WINDOWS\Internet Logs\xDB2E.tmp
2006-05-29 03:13 1,660,928 ----a-w C:\WINDOWS\Internet Logs\xDB2F.tmp
2006-05-25 01:24 2,360,320 ----a-w C:\WINDOWS\Internet Logs\xDB2B.tmp
2006-05-25 01:24 144,384 ----a-w C:\WINDOWS\Internet Logs\xDB2D.tmp
2006-05-24 02:21 2,374,144 ----a-w C:\WINDOWS\Internet Logs\xDB2A.tmp
2006-05-24 02:21 1,933,824 ----a-w C:\WINDOWS\Internet Logs\xDB2C.tmp
2006-05-23 01:28 2,358,272 ----a-w C:\WINDOWS\Internet Logs\xDB29.tmp
2006-05-18 01:57 2,356,224 ----a-w C:\WINDOWS\Internet Logs\xDB28.tmp
2006-05-16 01:59 2,633,216 ----a-w C:\WINDOWS\Internet Logs\xDB26.tmp
2006-05-16 01:59 2,347,520 ----a-w C:\WINDOWS\Internet Logs\xDB25.tmp
2006-05-07 04:02 2,326,528 ----a-w C:\WINDOWS\Internet Logs\xDB24.tmp
2006-05-07 04:02 1,738,240 ----a-w C:\WINDOWS\Internet Logs\xDB27.tmp
2006-05-03 01:17 2,322,944 ----a-w C:\WINDOWS\Internet Logs\xDB22.tmp
2006-05-03 01:17 2,185,216 ----a-w C:\WINDOWS\Internet Logs\xDB23.tmp
2006-05-02 01:07 2,317,312 ----a-w C:\WINDOWS\Internet Logs\xDB21.tmp
2006-04-28 04:15 2,644,992 ----a-w C:\WINDOWS\Internet Logs\xDB20.tmp
2006-04-28 04:15 2,310,144 ----a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2006-04-24 22:43 2,321,920 ----a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2006-04-17 01:08 2,271,744 ----a-w C:\WINDOWS\Internet Logs\xDB1C.tmp
2006-04-17 01:08 1,662,976 ----a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2006-04-12 01:11 2,269,696 ----a-w C:\WINDOWS\Internet Logs\xDB1B.tmp
2006-04-11 00:58 623,616 ----a-w C:\WINDOWS\Internet Logs\xDB1A.tmp
2006-04-11 00:58 2,263,552 ----a-w C:\WINDOWS\Internet Logs\xDB19.tmp
2006-04-06 23:08 271,872 ----a-w C:\WINDOWS\Internet Logs\xDB18.tmp
2006-04-06 23:08 2,260,480 ----a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2006-04-03 23:31 2,209,280 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2006-04-03 23:31 1,083,392 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2006-03-26 03:20 753,152 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2006-03-26 03:20 2,128,384 ----a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2006-03-21 02:12 711,680 ----a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2006-03-21 02:12 2,045,440 ----a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2006-03-16 02:19 2,025,984 ----a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2006-03-10 01:50 2,022,912 ----a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2006-03-04 03:24 32,256 ----a-w C:\WINDOWS\Internet Logs\xDBE.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-08-14 18:22 28672]
"monitr32"="C:\Program Files\Canon\MultiPASS4\monitr32.exe" [2001-08-21 17:52 311296]
"fxredir"="C:\WINDOWS\System32\fxredir.exe" [2001-08-21 17:49 65536]
"MPTBox"="C:\PROGRA~1\Canon\MULTIP~1\MPTBOX.EXE" [2001-08-21 17:52 151552]
"OmniPage"="C:\Program Files\Caere\OmniPagePro90\opware32.exe" [1998-10-12 18:13 44032]
"DwlClient"="C:\Program Files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 19:05 323584]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 10:29 40960]
"CTSysVol"="C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43 57344]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2005-01-26 04:23 902936]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-01 14:51 369664]
"Logitech Utility"="Logi_MwX.Exe" [2003-06-30 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2006-11-11 23:48 155136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
GoBack.lnk - C:\Program Files\Roxio\GoBack\GBTray.exe [2003-09-17 19:01:52]
Kodak EasyShare software.lnk - C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe [2002-09-16 15:42:06]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Forget Me Not.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Forget Me Not.lnk
backup=C:\WINDOWS\pss\Forget Me Not.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ItsDeductible7PopUp.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ItsDeductible7PopUp.lnk
backup=C:\WINDOWS\pss\ItsDeductible7PopUp.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
--------- 2002-12-17 12:28 684032 C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
--------- 2003-08-29 04:59 122880 C:\WINDOWS\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--------- 2005-03-23 14:34 58992 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--------- 2003-10-06 15:16 5058560 C:\WINDOWS\System32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--------- 2003-10-06 15:16 741376 C:\WINDOWS\SYSTEM32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
--a------ 2006-05-30 15:59 1003520 C:\Program Files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-12-15 03:23 75520 C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
--------- 2005-08-20 01:15 100056 C:\PROGRA~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--------- 2003-05-07 02:13 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 01:00 90112 C:\WINDOWS\UpdReg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--------- 2005-08-19 18:34 3084288 C:\Program Files\Yahoo!\Messenger\ypager.exe
R0 GBDevice;GBDevice;C:\WINDOWS\system32\drivers\GBDevice.sys [2002-01-21 12:37]
R0 GoBack2K;GoBack2K;C:\WINDOWS\system32\drivers\GoBack2K.sys [2002-01-21 12:36]
R2 cis1284;cis1284;C:\WINDOWS\System32\drivers\cis1284.sys [2001-06-26 21:00]
R2 GBFSHook;GBFSHook;C:\WINDOWS\system32\drivers\GBFSHook.sys [2002-01-21 12:37]
R2 WUSB54GSv2SVC;WUSB54GSv2SVC;"C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54GSv2.exe" []
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2004-06-23 16:10]
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-06-23 16:09]
R3 NPDriver;Norton Unerase Protection Driver;C:\WINDOWS\System32\Drivers\NPDRIVER.SYS [2005-01-24 15:38]
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-06-23 16:09]
S3 NMSCFG;NIC Management Service Configuration Driver;C:\WINDOWS\System32\drivers\NMSCFG.SYS [2002-10-10 04:18]
S3 NMSSvc;Intel® NMS;C:\WINDOWS\System32\NMSSvc.exe [2002-10-10 04:18]
S3 SDdriver;SDdriver;C:\WINDOWS\System32\Drivers\sddriver.sys [2005-01-24 15:18]
S3 WRSWanDD;iVasion PoET Adapter;C:\WINDOWS\system32\DRIVERS\WrKPoETNic2000.sys [2002-07-17 14:53]
*Newly Created Service* - GTNDIS5
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2006-12-30 03:00:00 C:\WINDOWS\Tasks\Backup.job"
- C:\WINDOWS\SYSTEM32\ntbackup.exe
"2007-02-16 22:39:31 C:\WINDOWS\Tasks\michele says clean up.job"
- C:\Program Files\Norton SystemWorks\OBC.exe,/SCHEDULE /NAME:michele says clean up /AUTO
"2007-02-17 17:59:41 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Jennifer.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
"2007-01-29 22:53:06 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2007-02-17 05:00:02 C:\WINDOWS\Tasks\Symantec Drmc.job"
- C:\Program Files\Common Files\Symantec Shared\SymDrmc.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-19 13:50:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DwlClient = C:\Program Files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x?e???????X:??????x???`???X??? ???????`???P???? ?w? ?w)??p????????(???}????U?w????????????0??????w, ?w?M?wW??w???w)??p????????x'@?????????X????????"@?e?????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-19 13:53:16